Unauthenticated File Access Vulnerability in MCP Atlassian for Confluence and Jira
CVE-2026-77248
8.6HIGH
What is CVE-2026-77248?
The MCP Atlassian server for Confluence and Jira has a vulnerability that allows unauthenticated network users to access files stored within the MCP process. Specifically, the transport mechanism accepts requests without requiring user validation and reverts to operator credentials, which introduces a risk of sensitive data exposure. Additionally, the file upload feature permits unrestricted file path parameters, enabling attackers to upload malicious content to user-defined Jira issues or Confluence pages. This vulnerability affects versions prior to 0.22.0 and has been addressed in the latest release, where the input validation process has been strengthened to mitigate these risks.
Affected Version(s)
mcp-atlassian < 0.22.0
